
內容簡介
UltimaTour Contact Forms 是一款獨立的聯絡表單建構器,讓使用者能快速創建專業的聯絡表單,並將其發佈在任何地方。所有的查詢都能在 WordPress 中有序管理,無需額外的帳號或付費計畫。
【主要功能】
• 無限表單,無提交數量限制
• 視覺化表單建構器,支援響應式佈局
• 提供多種欄位類型,如文本、電子郵件、上傳等
• 提交內容可存儲、搜尋及過濾
• 安全的單檔上傳及管理通知
• 支援 Cloudflare Turnstile 和 Google reCAPTCHA
外掛標籤
開發者團隊
原文外掛簡介
Create a professional contact form in minutes, publish it anywhere with a shortcode, and keep every inquiry organized inside WordPress.
UltimaTour Contact Forms is a complete standalone form builder. It does not require an UltimaTour account, a paid plan, an external form service, or another UltimaTour plugin. Build unlimited forms, accept unlimited legitimate submissions, send email notifications, collect secure uploads, and review responses from one focused WordPress workspace.
Built for real business inquiries
Use it for contact requests, quote requests, tour inquiries, employment applications, customer support, vendor questions, group requests, document collection, and more. Start with a ready-made form or build your own with the visual field editor and responsive column layouts.
Your submissions stay useful
Email is a notification, not your only archive. Submitted entries can be stored in WordPress, searched, filtered, reviewed, archived, exported, and erased through the WordPress privacy tools. Delivery status, security signals, and attachment details remain connected to the submission that produced them.
Security without punishing real visitors
Every submission passes server-side validation, signed timing checks, honeypot protection, rate limiting, duplicate detection, upload validation, and PSC request-integrity checks. CAPTCHA is optional. TrustEmporium advisory enrichment can add useful context when an administrator chooses to connect it, but it never replaces normal validation or silently rejects a legitimate inquiry.
Works alone. Works smarter with Operator.
Standalone sites receive the full core contact-form experience. When UltimaTour Operator is installed, Contact Forms can reuse Operator-managed business identity, branding, mail, CAPTCHA, audit, and TrustEmporium services instead of asking the administrator to configure the same information twice.
Five-minute start
Activate the plugin.
Open Contact Forms and edit the ready-to-use Partner Contact form.
Choose Publish, copy the shortcode, and place it on a page.
Send a test submission while logged out.
Review it under Contact Forms > Submissions.
No account, license key, CAPTCHA key, or Operator installation is required for those steps.
Features
Unlimited forms with no artificial submission cap.
Visual form builder with templates and responsive layouts.
Text, email, telephone, number, URL, choice, date, time, display, hidden, and upload fields.
Stored submission inbox with search, filters, status, notes, timeline, and pagination.
Administrator notifications and optional visitor confirmation emails.
Secure single-file uploads with protected administrator downloads.
Layered spam and request-integrity protection, even without CAPTCHA.
Optional Cloudflare Turnstile and Google reCAPTCHA support.
Accessible labels, grouped controls, error summaries, focus handling, and keyboard builder controls.
Hardened CSV export plus WordPress privacy export and erasure support.
Health Dashboard with clear status, explanations, and recommended actions.
Optional TrustEmporium advisory enrichment configured from inside Contact Forms.
Optional UltimaTour Operator integration with shared business services and no duplicate setup.
A Useful Path Into UltimaTour
Contact Forms remains fully useful on its own. When your needs grow, the plugin also provides three relevant, administrator-only ways to explore the wider UltimaTour ecosystem:
UltimaTour Operator reduces repeated setup by sharing business identity, branding, mail, CAPTCHA, audit, and connected services across compatible UltimaTour modules.
TrustEmporium provides optional advisory context for submitted contact details after the administrator deliberately connects the service.
UltimaTour Reviews and Partner provide operator discovery, product documentation, downloads, and support resources.
These links appear only inside the plugin administration interface. Contact Forms does not add advertising, backlinks, tracking, or UltimaTour branding to public forms, confirmation messages, or visitor emails.
Why Site Owners Choose Contact Forms
No form or submission limits
Create the forms your website needs and accept legitimate responses without metering, monthly submission allowances, or artificial upgrade walls.
No public advertising
Your website belongs to you. Public forms, confirmations, emails, and site footers are not used to advertise UltimaTour or insert automatic backlinks.
No hosted-form dependency
Core form building, rendering, validation, storage, uploads, and email notifications run through WordPress. Optional connected services are clearly disclosed and are not required for the core workflow.
Clear diagnostics
The Health Dashboard explains what happened, why it matters, and what to do next. Routine setup should not require reading logs, decoding error numbers, or contacting support.
Designed for long-term ownership
Forms, submissions, and settings remain under the website owner’s control. Contact Forms supports export, privacy erasure, retention controls, and clean standalone operation.
Email Template Variables
Contact Forms renders test emails, administrator notifications, and visitor confirmations through one merge-variable engine in standalone and Operator-integrated modes. Variables use the {variable} syntax.
Supported variables: {business_name}, {email}, {phone}, {home_url}, {website}, {logo_url}, {tagline}, {address}, {signature}, {footer}, {form_name}, {submission_id}, {submission_date}, {visitor_name}, {visitor_email}, {site_name}, and {current_year}.
Unknown variables are replaced with a blank value and logged safely for administrators. Visitor-submitted values are escaped by context and are not reparsed as template syntax.
External Services
CAPTCHA
CAPTCHA is an optional external challenge layer. In standalone mode, an administrator may configure Cloudflare Turnstile or Google reCAPTCHA with both site and secret keys, and may choose to require CAPTCHA before submissions are accepted. Pages containing configured CAPTCHA forms load the selected provider challenge script and submit the provider response token for server-side verification. Provider terms and privacy policies apply:
Cloudflare Turnstile setup: https://developers.cloudflare.com/turnstile/get-started/
Cloudflare Turnstile privacy: https://www.cloudflare.com/privacypolicy/
Cloudflare terms: https://www.cloudflare.com/website-terms/
Google reCAPTCHA version guide: https://developers.google.com/recaptcha/docs/versions
Google privacy: https://policies.google.com/privacy
Google terms: https://policies.google.com/terms
TrustEmporium
TrustEmporium enrichment is advisory. Contact Forms uses Operator-owned TrustEmporium services when UltimaTour Operator exposes a supported service. In standalone mode, an administrator can use Connect and Provision TrustEmporium inside Contact Forms to create or recover the site-specific TE partner contract and business account. Manual partner key and shared-secret entry remains available only as an advanced recovery path.
Standalone setup calls /te/v1/partner/contact-forms/self-issue-contract. TrustEmporium CORE verifies setup by requesting /wp-json/ultimatour-contact-forms/v1/trustemporium/onboarding-verification/{token} from the installing site before issuing credentials or provisioning the business account. Setup may transmit site URL, home URL, canonical domain, installation ID, plugin version, business name, primary contact email, locale, timezone, generated external business ID, verification URL, and verification token hash. The standalone connection test uses /te/v1/partner/ping only to confirm authentication and does not create or refresh TrustEmporium records.
Submission enrichment is lookup-only and uses /te/v1/partner/lookup; Contact Forms submissions must never call /te/v1/partner/event, /te/v1/partner/provision-business, self-issue TE contracts, create TE event/customer lifecycle records, write advisory records, create TE lookup-audit records, mint public TE lookup tokens, or consume TE allowance usage. A TrustEmporium submission-enrichment request may include the form ID, form name, submission ID, submitted contact name, submitted email address, submitted phone number, source URL, site identifier, request ID, correlation ID, idempotency key, and timing metadata. It does not include CAPTCHA secrets, TrustEmporium access keys, passwords, raw PSC values, PSC source words, uploaded file contents, full submission payloads, or private plugin credentials. Remote TE enrichment is blocked when Contact Forms health, integrity, compatibility, or local PSC state requires review. UltimaTour connected-service terms and privacy apply: https://partner.ultimatour.com/privacy-terms/
UltimaTour Mothership heartbeat
Operator-connected installs add a Contact Forms integrity block to the existing Operator heartbeat when Operator is communication-capable and do not run a parallel standalone heartbeat. When Operator is absent or not communication-capable, Contact Forms may use the approved standalone control-plane route for Contact Forms heartbeat duties. The Contact Forms heartbeat block reports module slug, module version, compatibility state, integration mode, reporting reason, health status, non-secret protected-file hashes, PSC package fingerprint/generation/status when PSC is enabled, TrustEmporium enabled/configured status, and a timestamp. It does not include form submission values, CAPTCHA tokens, secrets, passwords, raw PSC values, or PSC package source words. UltimaTour connected-service terms and privacy apply: https://partner.ultimatour.com/privacy-terms/
Polymorphic Semantic Canary
Polymorphic Semantic Canary (PSC) is an optional concealed request-integrity layer independently conceived by Michel Peter Johannes Wouterse, TE Systems LLC. PSC renders three signed hidden integrity fields from an active package and detects malformed, expired, duplicated, replayed, copied, swapped, or rewritten form-integrity values. Every installation always keeps three persistent 32-word local PSC artifacts outside the plugin folder, so forms and local protection continue during remote failure. Administrators own and may edit local artifacts when the site owns the local package. Operator-connected installs may receive signed installation-bound PSC data through the existing Operator heartbeat; Contact Forms verifies Ed25519 signature, key ID, fingerprint, installation UUID, version, issue/expiry state, exact 3×32 shape, replay state, and route before atomic activation. Standalone installs use the included local PSC artifacts. PSC packages contain data only: no remote PHP or JavaScript is downloaded, and no visitor submission is transmitted to obtain them. An invalid package never replaces the active package.
Stored submissions display a safe Security Signals audit panel. Operator-mode reCAPTCHA v3 scores come from Operator-owned CAPTCHA verification for the Contact Forms action. PSC risk scores come from Contact Forms request-integrity verification. These scores are separate and do not interfere with one another.
